Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
TEMPLATE · IT / OTv1.0 · REVIEWED 2026-07-28

90-Day Improvement Roadmap Template

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

A quarter-length roadmap organized by the six-stage sequence, with a current-and-target maturity column so progress is stated as a movement between defined levels rather than as a percentage nobody can audit.

How to use it

Set a target level per practice for the end of the quarter, not an aspiration for the year. Moving five practices from Configured to Deployed is a better quarter than moving twenty from Absent to Documented.

The maturity ladder

Score each practice against this ladder. The distinction that matters most is between having a tool, deploying it to the correct scope, and operating it consistently.

LevelNameWhat it meansThe question that separates it from the level below
0AbsentThe capability does not exist in any form.Is there anything at all — a tool, a document, a person who owns it?
1DocumentedIntent exists on paper. Deployment has not happened or is incomplete.Is the intent written down, with a named owner and a scope?
2ConfiguredThe technology or process is configured, but not yet applied to the intended scope.Is it switched on and set up somewhere — even if only in part of the estate?
3DeployedIt is applied across the scope it was meant to cover.Does it cover everything in scope, with the exceptions written down?
4OperatingIt functions consistently during normal operations, not only when someone is watching.Does it keep working through a normal month without manual rescue?
5MeasuredCoverage and effectiveness are measured, monitored, and exception-handled.Can you state a number for coverage or effectiveness, and show the trend?
6GovernedOwnership, scheduled review, continuous improvement, and evidence retention are established.Is there an accountable owner, a review cadence, and retained evidence?

Stage 1 — Know and control

See every identity and asset you defend.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-01 — Phishing-resistant MFAIT-02    
IT-02 — Asset inventory    
OT-01 — OT identity and access controlOT-02    
OT-02 — Validated OT asset inventory    

Stage 2 — Contain compromise

Keep one breached device from becoming ten.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-05 — Logical segmentationIT-02    
OT-03 — OT network segmentationOT-02    
OT-06 — OT remote access pathwaysOT-03, OT-01    

Stage 3 — Reduce exposure

Close the gaps attackers reach first.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-03 — Technical debt reductionIT-02    
IT-06 — Risk-based vulnerability managementIT-02, IT-03    
OT-05 — OT vulnerability managementOT-02, OT-03    

Stage 4 — Recover operations

Prove you can restore before you need to.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-09 — Backup and disaster recoveryIT-02, IT-01    
OT-04 — OT incident response and recoveryOT-02, OT-08    
OT-08 — OT system resiliencyOT-02    

Stage 5 — Engineer securely

Build new capability without new risk.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-04 — Flexible technology stackIT-02, IT-03    
IT-07 — Security in the development lifecycleIT-02    
IT-08 — Secure AI adoptionIT-02    
OT-09 — OT supply chain securityOT-02, OT-06    
OT-10 — OT change review    

Stage 6 — Sustain performance

Keep your people and monitoring sharp.

PracticeDepends onCurrent levelTarget levelOwnerBy when
IT-10 — Technical workforce readiness    
OT-07 — OT continuous monitoringOT-02, OT-03    

Quarterly review

  • Which practices moved a level, and what is the evidence for the move?
  • Which targets were missed, and was the cause capacity, funding, or dependency?
  • Which dependencies blocked work that we did not anticipate?
  • What did we learn that changes next quarter's targets?

Reviewed by

NameRoleDate
   
   
   

Limitations

90-Day Improvement Roadmap Template · version 1.0 · reviewed 2026-07-28 · file name batb-90-day-improvement-roadmap-template

Generated from Build your plan at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-90-day-improvement-roadmap-template to keep filenames consistent across your team.